Specifications

Security
4-82 Advanced Configuration
PreAuthentication.IfPreAuthenticationisenabled,aWPA2wirelessclientcanperforman
802.1Xauthenticationwithotherwirelessaccesspointsinitsrangewhenitisstillconnectedto
itscurrentwirelessaccesspoint.
TousePreAuthentication,youmusthavethefollowing:
WirelessnetworkadaptorsthatsupportWPA2.
–WindowsXPwirelessnetworkadaptordriversthatsupportthepassingofWPA2
capabilitiestoWindowsWirelessAutoConfiguration.
Authentication
OpenSystem(thedefaultsetting):SelectthisoptionifyouplantouseWPAor802.1xasa
securitymechanism.Ifyoudon’tsetupanyothersecuritymechanismontheaccess
point,
thenetworkhasnoprotectionandisopentoallusers.
SharedKeysetstheaccesspointtouseWEPsharedkeys.Ifthisoptionisselected,you
mustconfigureatleastonekeyontheaccesspointandallclients.
WPA(WiFiProtectedAccess)isastandardsbased,
interoperablesecurityenhancement
thatstronglyincreasesthelevelofdataprotectionandaccesscontrolforexistingand
futurewirelessLANsystems.Itisderivedfromandwillbeforwardcompatiblewiththe
upcomingIEEE802.11istandard.WPAleveragesTKIP(TemporalKeyIntegrityProtocol)
fordataprotectionand802.1Xfora uthenticated
keymanagement.
WPAPSK.UsesWPAkeymanagement,nonrootaccesspoint/bridg esandthe
authenticationserverauthenticatetoeachotherusinganEAPauthenticationmethod,and
thenonrootaccesspoint/bridgeandservergenerateapairwisemasterkey(PMK).Using
WPA,theservergeneratesthePMKdynamicallyandpassesit
totherootaccesspoint/
bridge.UsingWPAPSK,however,youconfigureapresharedkeyonboththenonroot
accesspoint/bridgeandtherootaccesspoint/bridge,andthatpresharedkeyisusedas
thePMK.
WPA2providesastrongerencryptionmechanismthroughAES,whichisarequirement
for
somecorporateandgovernmentusers.TKIP,theencryptionmechanisminWPA,
reliesonRC4insteadofTripleDataEncryptionStandard(3DES),AES,oranother
encryptionalgorithms.
WPAWPA2‐MixedpermitsthecoexistenceofWPAandWPA2clientsonacommonSSID.
WPA2‐mixedmodeisaWiFiCertifiedfeature.
Theaccesspointadvertisesthe
encryptionciphers(TKIP,CCMP,other)thatareavailableforuse.Theclientselectsthe
encryptioncipheritwouldliketouse,andtheselectedencryptioncipherisusedfor
encryptionbetweentheclientandaccesspointonceitisselectedbytheclient.
DataEncryptionenables
ordisablestheaccesspointtouseWEPsharedkeysfordata
encryption.Ifthisoptionisselected,youmustconfigureat
leastonekeyontheaccesspoint
andallclients.(Default:Disable
)
WPAClientssetsthespecifiedradiointerfaceorVAPto:
Required‐allowsonlyWPAenabled clientstoaccessthenetwork.
Note: To use 802.1x on wireless clients requires a network card driver and 802.1x
client software that supports the EAP authentication type that you want to use.
Windows XP provides native WPA support, other systems require additional software.
Note: You must enable WEP encryption in order to enable all types of encryption on the access
point; however, you do not need to define WEP keys for WPA.